Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

AuditWizard Log File Information Disclosure Vulnerability

AuditWizard is prone to an information-disclosure vulnerability because the application fails to properly ensure that sensitive information is not disclosed to local users.

This issue allows local attackers to gain access to sensitive administrative account-authentication credentials.

Reportedly, the vendor may have reissued version 6.3.2 with fixes that address this issue; Symantec has not confirmed this.







 

Privacy Statement
Copyright 2009, SecurityFocus